Automatically translated.View original post

Hackers using AI Agents to raid Thai Treasury

Hackers use AI Agents to raid Thai Treasury

According to a report by the website, The Record, a research team from Hunt.io a cybersecurity expert firm revealed that a hack was detected to infiltrate the Thai Ministry of Finance's system, which was detected by hackers who accidentally left the tools used to access the Thai Ministry of Finance's systems on the infrastructure that public users can access. These tools include malware, scripts for attacks, stolen passwords, and, most importantly, a log file. The remaining AI Agents have been investigated. In the field of hacking operations, the research team has not yet been able to determine which channel the hackers used to access the system at the first point, but it has been found that hackers have successfully accessed various Treasury subsystems. Hackers have searched files and classified information, stored detailed system information, and tried to upgrade the right to use the system higher than it is today.

The interesting thing is that the AI Agent that hackers use to access the system is an AI Agent called Hermes, which was developed by Nous Research and released to the public earlier this year. Hackers set up the AI Agent to run in YOLO mode, a mode in which the AI will automatically run everything by itself without waiting for human commands. All of the above operations have been determined by the research team to be the work of this AI Agent. In addition, malware is used. The system back door (Backdoor) type in the Hades family opens to create victim system access permanence (Persisrtence), with such malware supporting use on both Windows and Linux operating systems.

After the research team detected the operation, the research team reported on related agencies, the National Computer Security Coordination Center (ThaiCERT) and the National Cyber Security Administration (SOK). On July 15, the research team also revealed that the hacking operation may have begun in mid-June. The people behind it have not yet been identified, but they are expected to be a group of hackers from China. But the good news is that the team has not yet found evidence that the information stolen by the hackers has been smuggled back to the hackers' C2 or Command and Control servers.

At the time of the news, there were no reports that the Treasury and the ministers involved had commented to acknowledge or recognize that the system had been compromised.

# Trending # lemon 8 diary # Treasury # Thai # freedomhack

8/22 Edited to

... Read moreจากประสบการณ์ส่วนตัวในวงการความปลอดภัยไซเบอร์ ผมเห็นการใช้ AI Agent อย่าง Hermes เพื่อโจมตีระบบสำคัญ เช่น กระทรวงการคลังของไทย แสดงให้เห็นถึงเทคโนโลยีที่ล้ำหน้าของแฮกเกอร์ในปัจจุบัน โดยเฉพาะโหมด YOLO ที่ทำให้ AI ทำงานได้อัตโนมัติโดยไม่ต้องรอคำสั่งมนุษย์ ซึ่งเพิ่มความรวดเร็วและความซับซ้อนของการโจมตีอย่างมาก มัลแวร์ Backdoor ในตระกูล Hades ที่สามารถรันได้ทั้งบน Windows และ Linux ยังทำให้แฮกเกอร์มีความสามารถในการคงอยู่ในระบบเหยื่อได้นานมากขึ้น เรียกได้ว่าเป็นภัยคุกคามที่ท้าทายการป้องกันทางไซเบอร์อย่างมาก ผมแนะนำว่าองค์กรที่เกี่ยวข้องควรตรวจสอบระบบโครงสร้างพื้นฐานอย่างใกล้ชิด และอัพเดตระบบความปลอดภัยรวมถึงอุปกรณ์ตรวจจับพฤติกรรมการใช้ AI Agent รวมถึงการทำ Log Monitoring ที่เข้มงวด เพื่อป้องกันช่องโหว่ที่อาจเกิดขึ้นได้ในอนาคต การรับมือกับภัยคุกคามที่ใช้ AI เป็นสิ่งสำคัญที่องค์กรทุกระดับต้องเตรียมพร้อมอย่างจริงจัง การโจมตีผ่าน AI Agent ที่ถูกตั้งค่าให้ทำงานอัตโนมัตินี้ถือเป็นบทเรียนที่ดีสำหรับทุกฝ่ายในการวางแผนรับมือเรื่องความปลอดภัยไซเบอร์ และชี้ให้เห็นถึงการเปลี่ยนแปลงรูปแบบของแฮกเกอร์ที่นำเทคโนโลยีสมัยใหม่มาใช้ประโยชน์อย่างเต็มที่ การเสริมสร้างความรู้ความเข้าใจให้กับพนักงานและผู้ดูแลระบบเป็นสิ่งจำเป็นไม่แพ้กัน เพื่อรับมือกับเทคนิคแฮกที่พัฒนาเรื่อยๆ ในยุคปัจจุบัน